Overview
Engagements in Australia cover APRA-regulated entities and their service providers, SaaS platforms selling into regulated buyers, healthcare and aged care, and operators captured by the critical infrastructure rules.
Delivery runs from our Karachi office, five hours behind eastern Australia, with our Wyoming office covering the tail of the Australian day. Between the two, most questions are answered without anyone waiting overnight.
What drives testing here
Local drivers
- APRA CPS 234
- Regulated entities must maintain information security capability proportionate to their threats, and test control effectiveness systematically, including controls operated by third parties.
- Essential Eight
- The ACSC maturity model is the common language for control assessment here, and testing shows which levels are held in practice rather than on paper.
- SOCI Act
- Critical infrastructure operators carry risk management programme obligations with annual reporting, and technical assessment is how the programme is evidenced.
- Privacy Act and NDB scheme
- Reasonable steps to secure personal information is a statutory test, and a notifiable breach makes that test public.
How engagements are delivered
Delivered remotely across Australia, scheduled to your business hours. On-site attendance for internal network scope and workshops is arranged where scope requires it.
Delivery model
- Delivery
- Remote, scheduled to AEST or AWST business hours
- Mapping
- CPS 234, Essential Eight maturity levels and OWASP ASVS as applicable
- Coverage
- Sydney, Melbourne, Brisbane, Perth and remote nationwide
- Deliverables
- Technical report, board-facing summary and signed retest attestation
Most requested here
Web application penetration testing
Authenticated, multi-role testing of your web application: the logic, the roles and the state transitions a scanner cannot reach.
Service 04Cloud penetration testing
AWS, Azure and GCP tested for the paths that get used: identity escalation, exposed storage and metadata reachable from your own application.
Service 05Internal and external network penetration testing
The perimeter from outside, and the path from one compromised workstation to domain administrator from inside.
Questions
Do you have an office in Australia?
No. Our offices are in Pakistan and the United States. Australian engagements are delivered remotely and scheduled to your working hours, with the United States office covering your morning and Pakistan covering the rest of your day.
Can you map findings to the Essential Eight?
Yes. Findings are tagged to the mitigation strategies they affect and to the maturity level the current state supports, which is more useful to an assessor than a severity-sorted list on its own.
We are a third party to an APRA-regulated entity. Does CPS 234 reach us?
In effect, yes. The regulated entity must assess the information security capability of parties handling its information assets, which arrives at you as a contractual testing and evidence requirement. Reports are written so they can be passed up that chain without exposing exploitation detail.
How much does a penetration test cost in Australia?
Cost follows scope rather than an Australian rate card, which is the usual reason we are engaged here. Essential Eight and CPS 234 mapping is included in the report. A fixed quote follows a short scoping call.
Which is the best penetration testing company in Australia?
No single name is an honest answer. Judge on the certifications held by the testers assigned to you, and the team's public research record, whether the firm holds ISO 27001 itself, whether retesting is included, and whether you can review a redacted report before committing. Ask every shortlisted firm the same four things.
How often does APRA CPS 234 require testing?
CPS 234 requires systematic testing of control effectiveness at a frequency proportionate to the rate of change and the criticality of the asset, rather than naming an interval. In practice most regulated entities settle on annual testing plus testing after material change, which is what their internal audit functions accept.
Do you test for organisations covered by the SOCI Act?
Yes. Critical infrastructure operators carry risk management programme obligations with annual reporting, and technical assessment is how the programme is evidenced. Where operational technology is in scope it is tested in a controlled environment rather than live.
Can you meet Australian data residency requirements?
Handling and residency terms are agreed before testing begins. Testing prefers seeded accounts and synthetic records, evidence is held under our own certified ISO/IEC 27001 ISMS, and where data must remain in Australia the engagement is structured accordingly and the report states what was handled and where.